blob: e59c4834fd478361a58bc420a432b81b502fa230 (
plain)
1
2
3
4
5
6
7
8
9
10
11
|
mac-robber is a Forensics & Incident Response tool used to collect
the Modified, Access, and Change (MAC) times from allocated files.
It recursively reads MAC times of files and directories and prints
them in 'time machine' format to STDOUT. This format is the same
that the mactime tool from The Coroners Toolkit (TCT) reads.
mac-robber is based on the grave-robber tool from The Coroners
Toolkit (TCT) when using the '-m' flag, except it does not require
Perl!
WWW: http://www.sleuthkit.org/mac-robber/desc.php
|